Back to skill

Security audit

Henry OS

Security checks for vulnerabilities and agentic risk

Overview

This skill describes a powerful autonomous assistant, but its installer is unreviewable and its privacy/control claims are under-scoped for the access it requests.

Review this carefully before installing. Do not run the one-line installer unless you can independently inspect and verify the exact install script. The skill would likely need broad access to communications, contacts, calendars, local projects, network services, and persistent background agents, so install only if the publisher provides a pinned, auditable installer and clear approval/data-flow controls.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:50
Finding

Unverified Remote Shell Script Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:46-51, SKILL.md:254-259, and skill.json:13
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code

SKILL.md:46-51:

markdown
### One-Line Install

```bash
curl -fsSL https://henryos.ai/install.sh | bash
text

`SKILL.md:254-259`:

```markdown
**Problem**: Install script fails with permission error
```bash
# Solution: Run with explicit bash
bash -c "$(curl -fsSL https://henryos.ai/install.sh)"
text

`skill.json:13`:

```json
"install": "curl -fsSL https://henryos.ai/install.sh | bash",

Technical Analysis

The installation instructions retrieve a mutable shell script from https://henryos.ai/install.sh and immediately pass it to Bash. Neither installation method provides version pinning, checksum validation, cryptographic signature verification, or an opportunity to inspect the script before execution.

Consequently, the code examined during this audit is not the effective installation payload. The remote server, its hosting provider, DNS resolution, or any compromised deployment pipeline could alter the script after the Skill has been reviewed. The use of HTTPS protects the connection in transit but does not establish that the returned script is an immutable or independently verified artifact.

The alternative troubleshooting command does not mitigate the issue. It downloads the same remote content and executes it through bash -c, preserving the remote-code-execution risk.

Attack Path

  1. A user or agent follows the documented one-line installation command.
  2. The command connects to henryos.ai and retrieves the current contents of install.sh.
  3. The downloaded content is passed directly to Bash without integrity or authenticity verification.
  4. A compromised server, domain, DNS path, hosting account, or release pipeline supplies a modified script.
  5. Bash ...[truncated 1103 chars]
Remediation
View remediation

Remediation Suggestions

  1. Include the complete installer in the reviewed Skill package rather than downloading executable shell code at runtime.
  2. Replace curl | bash and bash -c "$(curl ...)" with a staged installation process:
    bash
    curl -fSLo install.sh https://example.invalid/releases/v1.0.0/install.sh
    echo "EXPECTED_SHA256  install.sh" | shasum -a 256 -c -
    less install.sh
    bash install.sh
    
  3. Host installers under immutable, versioned release URLs instead of a mutable /install.sh endpoint.
  4. Publish SHA-256 checksums through an independently authenticated release channel.
  5. Cryptographically sign release artifacts and verify signatures before execution.
  6. Ensure the installer runs without elevated privileges by default. Isolate any operation requiring elevation and explain why it is necessary.
  7. Document every filesystem modification, background service, scheduled task, network endpoint, and permission requested by the installer.
  8. Add automated release controls to ensure the packaged Skill version corresponds exactly to the verified installer version.

T08 · Insecure Dependencies

Error
Location
skill.json:13
Finding

Declared Local Entrypoint Is Missing and Replaced by an Unpinned External Installer

Content
View full analysis

Vulnerability Details

File Location: skill.json:13-17
Vulnerability Type: Insecure and unverifiable software supply chain
Risk Level: High

Vulnerable Code

json
"install": "curl -fsSL https://henryos.ai/install.sh | bash",
"entry": {
  "type": "script",
  "file": "install.sh"
}

The audited project contains only SKILL.md, skill.json, and icon.svg; the declared install.sh entrypoint is absent.

Technical Analysis

The metadata declares install.sh as the Skill's script entrypoint, but that file is not included in the supplied project. At the same time, the installation command obtains an unpinned script from an external website.

This prevents a reviewer or consumer from establishing a reproducible relationship between Skill version 1.0.0 and the installer that will actually execute. Two users installing the same published Skill version at different times may receive different code without any change to the audited package or its version.

The missing local entrypoint also means that the advertised installer behavior, dependencies, permission requests, persistence mechanisms, and data handling cannot be verified from the package. This is a supply-chain integrity failure rather than proof that a particular hidden payload currently exists.

Attack Path

  1. The package advertises install.sh as its script entrypoint.
  2. The local file is unavailable, preventing inspection or execution of a package-pinned installer.
  3. A user follows the external installation command instead.
  4. The external endpoint returns code that is not tied cryptographically to version 1.0.0.
  5. The endpoint or its release pipeline is modified or compromised.
  6. Replacement installer code executes while still appearing to originate from the unchanged Skill release.

Impact Assessment

The issue undermines auditability, reproducibility, and release integrity. Depending on the contents served ...[truncated 581 chars]

Remediation
View remediation

Remediation Suggestions

  1. Add the declared install.sh file to the Skill package and ensure it is included in the published artifact.
  2. Make the entry.file field reference an existing, reviewable, package-relative file.
  3. Remove the mutable remote installer command from skill.json.
  4. Tie every released Skill version to an immutable source commit and versioned installer artifact.
  5. Pin external dependencies to exact versions and verify their checksums or signatures.
  6. Add packaging validation that rejects releases when declared entrypoints are missing.
  7. Provide a software bill of materials listing installed components and their verified sources.
  8. Publish the installer source and generated release artifacts through the repository referenced in the metadata so consumers can independently compare them.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
75% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
# Henry OS — AI Chief of Staff Framework

> **Stop being the bottleneck in your own business.**

Henry OS transforms OpenClaw into a fully autonomous business partner that runs 24/7 — finding opportunities, managing your pipeline, handling communications, and executing tasks while you focus on high-leverage work.

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

Fetching and executing a shell script from an external domain creates a direct remote code execution risk during installation. Because the command is presented as the primary install path, users are encouraged to trust network-delivered code without verification, amplifying supply-chain exposure.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

One-Line Install

bash
curl -fsSL https://henryos.ai/install.sh | bash

That's it. Henry OS installs in under 5 minutes and starts working immediately.

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The command chaining into '| bash' is specifically dangerous because it converts downloaded content immediately into executed shell commands. This removes inspection and compounds the risk of any upstream compromise, typo-squatted domain, or malicious script modification.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

One-Line Install

bash
curl -fsSL https://henryos.ai/install.sh | bash

That's it. Henry OS installs in under 5 minutes and starts working immediately.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document claims the product works 'entirely offline after installation' while earlier sections describe monitoring inboxes, job boards, social channels, and other online services. This is a materially misleading security/privacy claim that can cause users to grant excessive trust or permissions under false assumptions about network exposure and data handling.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The command curl -fsSL https://henryos.ai/install.sh | bash fetches executable code from an external origin and runs it immediately, which is a classic arbitrary code execution risk. In the context of an agent skill installer, this is more dangerous because installation may occur with elevated privileges or broad access to local credentials, configuration, and automation environments.

Content

Scanner excerpt · skill.json (reported line 13)May include surrounding context.

json
"openclaw": ">=2026.1.0",
    "node": ">=20.0.0"
  },
  "install": "curl -fsSL https://henryos.ai/install.sh | bash",
  "entry": {
    "type": "script",
    "file": "install.sh"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Piping a remote script directly to bash executes unreviewed code from the network with the user's privileges and removes the opportunity to inspect integrity or contents first. If the hosting domain, transport, or script is compromised, installation becomes an immediate arbitrary code execution path.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill states that sensitive actions require explicit approval, but other sections emphasize autonomous execution, continuous operation, and automatic application of techniques to active projects. This inconsistency can mislead users about control boundaries and may result in unexpected outbound actions or changes being performed without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest’s install command downloads a remote shell script and immediately executes it via bash, giving the remote server full code execution during installation. This is dangerous because users cannot inspect, pin, or verify the fetched content, and any compromise of the domain, CDN, TLS termination, or upstream script would result in arbitrary command execution on the host.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The configuration example sets timezone to Australia/Brisbane as the shown value, with no accompanying note that users should choose their own locale. This can be interpreted as forcing a specific locale in user-facing setup guidance rather than explicitly making locale selection opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.